Security checks for vulnerabilities and agentic risk
Overview
The skill is a coherent Huawei Cloud SWR administration package, but it includes high-impact cloud operations through an executable helper that can create billable resources or delete registry instances without code-enforced confirmation.
Install only for operators who intentionally want an agent to administer Huawei Cloud SWR enterprise resources. Use least-privilege IAM credentials, prefer temporary credentials, confirm exact targets before create/delete/network-exposure actions, avoid allow-all public whitelist settings, and do not let the helper script be called automatically for create/delete without an explicit human-approved plan.
The helper submits an authenticated DeleteInstance request as soon as the delete subcommand is selected. It does not require an interactive confirmation, a target-bound confirmation token, or an explicit destructive-action acknowledgement.
This conflicts with the authorization workflow in SKILL.md, which requires confirmation before destructive operations. Documentation-only confirmation is not an effective security control because the helper is independently executable by an Agent or another local caller. The optional delete_obs and delete_dns values can expand the operation to associated storage and DNS resources without a separate confirmation boundary.
The operation uses the Huawei Cloud credentials available in the process environment. Therefore, the deletion is performed with all SWR deletion privileges granted to those credentials.
Attack Path
Huawei Cloud credentials with SWR deletion privileges are configured in the environment.
An Agent, automa
...[truncated 1163 chars]
Remediation
View remediation
Remediation Suggestions
Require a machine-enforced confirmation argument bound to the exact target, such as:
bash
--confirm-delete=<instance-id>
Reject the operation unless it exactly matches --instance_id.
Default to a dry-run mode that displays the target instance, region, project, and affected related resources.
Require separate explicit acknowledgements for OBS and DNS deletion rather than treating them as ordinary Boolean options.
Where interactive execution is supported, require the user to re-enter the target instance ID.
Consider querying and displaying the instance name and project before accepting confirmation.
Ensure the Agent-facing workflow never constructs the confirmation value unless the user has explicitly approved the displayed deletion plan.
Add automated tests verifying that deletion requests cannot reach client.delete_instance() without valid target-specific confirmation.
T09 · Insecure Skill Coding Practices
Warning
Location
scripts/swr_instance_helper.py:99
Finding
Paid SWR Instance Creation Does Not Enforce Mandatory Billing Consent
Content
View full analysis
Vulnerability Details
File Location: scripts/swr_instance_helper.py, lines 99–126 and 392–410 Vulnerability Type: Missing authorization confirmation for billable resource creation Risk Level: Medium
Vulnerable Code
python
body = CreateInstanceRequestBody(
name=args.name,
spec=args.spec,
charge_mode=args.charge_mode or "postPaid",
vpc_id=args.vpc_id,
subnet_id=args.subnet_id,
project_id=project_id,
enterprise_project_id=args.enterprise_project_id or "0",
description=args.description or None,
enable_intranet_access=args.enable_intranet_access if args.enable_intranet_access is not None else True,
obs_encrypt=args.obs_encrypt if args.obs_encrypt else None,
encrypt_type=args.encrypt_type or None,
obs_bucket_name=args.obs_bucket_name or None,
obs_enc_kms_key_id=args.obs_enc_kms_key_id or None,
)
request = CreateInstanceRequest(body=body)
try:
response = client.create_instance(request)
result = response.to_dict()
print(json.dumps(result, indent=2, ensure_ascii=False))
return result
except Exception as e:
print(f"ERROR: CreateInstance failed: {e}", file=sys.stderr)
sys.exit(1)
The same direct dispatcher makes the creation path independently callable:
The helper defaults charge_mode to postPaid and immediately submits the instance creation request. It does not require an accept-billing option, an interactive approval, or a validated record that the user reviewed the selected specification and related configuration.
SKILL.md identifies explicit billing consent as mandatory before operations and states that enterprise instance creation incurs hourly charges. Because the helper is the primary executable workaround for the do
...[truncated 1346 chars]
Remediation
View remediation
Remediation Suggestions
Require an explicit --accept-billing flag before submitting a creation request.
Bind approval to a displayed creation plan containing the instance name, specification, region, project, enterprise project, VPC, subnet, and charge mode.
Default to a dry run that prints the planned request without creating resources.
For Agent invocation, require a structured confirmation value generated only after the user explicitly approves the exact plan.
Reject unsupported charge modes and retain postPaid only after explicit acceptance.
Reconfirm if any billing-relevant parameter changes after approval.
Add tests that assert client.create_instance() is never called unless billing consent has been supplied and validated.
MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (48)
Tp4
High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill claims broad hcloud CLI-based management, but it also directs use of a Python helper script/SDK path and references capabilities that are not clearly implemented in the file itself. This mismatch is dangerous because users and orchestrators may trust the declared behavior while the skill can route execution through less-reviewed helper code or undocumented flows, weakening security review and change control.
Content
No source excerpt is available for this finding.
Credential Access
High
Category
Privilege Escalation
Confidence
91% confidence
Finding
The skill explicitly includes obtaining instance access credentials, which is a high-risk capability in a cloud registry context. Credential issuance can grant registry access, enable image exfiltration or tampering, and facilitate lateral movement if the agent is tricked into creating or revealing tokens for an unauthorized request.
Content
Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.
md
- Manage instance namespaces with security scanning and vulnerability blocking
- Configure instance registries for cross-instance image sync
- Query and manage instance repositories and artifacts
- Obtain instance access credentials (long-term and temporary)
- Configure instance network access (internal VPC endpoints, public access with whitelist)
- Manage custom domains for instance access
- Monitor instance statistics and job status
Credential Access
High
Category
Privilege Escalation
Confidence
92% confidence
Finding
The documented ability to create long-term and temporary instance credentials is inherently sensitive because it enables generation of new authentication material. In this skill's context, that is more dangerous than normal read-only administration because it can create durable access paths to private registries and downstream CI/CD systems.
Content
Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.
# Create a long-term access credential
hcloud SWR CreateInstanceLtCredential --instance_id=<instance-id> --name=my-credential --cli-region=cn-north-4
# Create a temporary access credential
Credential Access
High
Category
Privilege Escalation
Confidence
92% confidence
Finding
The temporary credential creation flow still represents direct access-token issuance and can be abused for unauthorized pulls, pushes, or replication if improperly triggered. Even short-lived credentials can be immediately weaponized or harvested from logs/output if the execution environment is not tightly controlled.
Content
Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.
md
# Create a long-term access credential
hcloud SWR CreateInstanceLtCredential --instance_id=<instance-id> --name=my-credential --cli-region=cn-north-4
# Create a temporary access credential
hcloud SWR CreateInstanceTempCredential --instance_id=<instance-id> --cli-region=cn-north-4
# List long-term credentials
Credential Access
High
Category
Privilege Escalation
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Content
Scanner excerpt · SKILL.md (reported line 494)May include surrounding context.
md
- **Default domain cannot be deleted** — only custom domains can be removed
- **AK/SK must never be hardcoded** — use environment variables only
- **Pagination offset must be multiple of limit** — `offset` must be 0 or a multiple of `limit`
- **Registry credential.access_secret is sensitive** — never expose or log access secrets
## Common Pitfalls
Tool Parameter Abuse
High
Category
Tool Misuse
Confidence
85% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Content
Scanner excerpt · references/cli-installation-guide.md (reported line 20)May include surrounding context.
The documented --credential.access_secret parameter is not itself malicious, but in this guide it is paired with examples that encourage supplying secrets directly on the CLI. In a security-sensitive agent context, that pattern risks disclosure through shell history, process inspection, CI logs, and captured transcripts.
Content
Scanner excerpt · references/swr-instance-api-guide.md (reported line 326)May include surrounding context.
Credential-creation functionality is inherently sensitive because it can mint reusable access to the registry. In this skill context, that sensitivity becomes security-relevant because the guide lacks accompanying guardrails on approval, storage, scoping, auditing, and revocation of newly created credentials.
Content
Scanner excerpt · references/swr-instance-api-guide.md (reported line 623)May include surrounding context.
Temporary credential creation is a legitimate feature, but it still grants access and should be treated as a sensitive action. Without warnings about handling, TTL, scope, output redaction, and revocation/expiry expectations, the guide may lead to accidental credential leakage or misuse.
Content
Scanner excerpt · references/swr-instance-api-guide.md (reported line 637)May include surrounding context.
Use Case: Long-term credentials for CI/CD pipelines and automation tools.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Content
Scanner excerpt · references/task-instance-credentials.md (reported line 23)May include surrounding context.
md
## Workflows
### W1: Create a Long-term Access Credential
Long-term credentials are suitable for CI/CD pipelines, automation tools, and persistent access.
Credential Access
High
Category
Privilege Escalation
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Content
Scanner excerpt · references/task-instance-credentials.md (reported line 53)May include surrounding context.
md
## Workflows
### W1: Create a Long-term Access Credential
Long-term credentials are suitable for CI/CD pipelines, automation tools, and persistent access.
Missing User Warnings
High
Category
Not specified by scanner
Confidence
98% confidence
Finding
The example explicitly shows configuring the whitelist as 0.0.0.0/0, which fully exposes the public endpoint to any source IP. Even though it says 'use with caution,' the example is still copy-pasteable and effectively demonstrates how to remove network-layer access restrictions from a registry service that may store sensitive images and supply-chain artifacts.
Content
No source excerpt is available for this finding.
Undeclared Tool Scope
Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill documents access to environment-based cloud credentials (AK/SK, security token) and operational CLI usage, but it declares no explicit tool scope or permission boundaries. That increases the chance an agent can invoke environment-backed actions without a constrained execution contract, which is risky for a skill capable of provisioning, deleting, and exposing registry infrastructure.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding
The trigger list includes broad phrases like 'instance repository', 'instance domain', and 'sync target' without clear constraints. Overbroad triggers can cause accidental activation in unrelated contexts, leading an agent to access credentials, modify cloud resources, or perform destructive actions when the user did not intend to invoke this high-privilege skill.
Content
No source excerpt is available for this finding.
Unsafe Defaults
Medium
Category
Tool Misuse
Confidence
84% confidence
Finding
The skill includes a documented high-risk path for enabling anonymous access (--anonymous_access=true). Although it warns about the risk, embedding this insecure configuration in a general-purpose admin skill increases the chance of accidental or socially engineered exposure of registry contents, especially when combined with broad triggers and missing tool-scope constraints.
Content
Scanner excerpt · SKILL.md (reported line 438)May include surrounding context.
md
| Operation | CLI Command | Risk Level | Confirmation Required |
| --------- | ----------- | ---------- | -------------------- |
| CreateInstance | `hcloud SWR CreateInstance` | High | Creating a paid instance incurs costs. Confirm instance spec (`swr.ee.basic` or `swr.ee.professional`), VPC/subnet configuration, and enterprise project before proceeding. |
| UpdateInstanceConfiguration | `hcloud SWR UpdateInstanceConfiguration --anonymous_access=true` | High | Enabling anonymous access allows unauthenticated users to pull images, reducing security. Confirm this is intended before proceeding. |
| CreateInstanceEndpointPolicy | `hcloud SWR CreateInstanceEndpointPolicy --enable=true` | Medium | Enabling public access exposes the instance to the internet. Must configure IP whitelist via `UpdateInstanceEndpointPolicy` to restrict access. Confirm before proceeding. |
| DeleteInstanceLtCredential | `hcloud SWR DeleteInstanceLtCredential` | Medium | Deleting a credential immediately revokes access for CI/CD pipelines using it. Recommend disabling the credential first (`UpdateInstanceLtCredential --enable=false`), verifying no active pipelines, then deleting. |
| CreateInstanceRegistry | `hcloud SWR CreateInstanceRegistry` | Medium | Creating a sync target registry stores the target registry authentication credentials (`access_key`/`access_secret`). Confirm the target registry URL and credential information before proceeding. |
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The uninstall section instructs users to delete both the CLI binary and the entire ~/.hcloud directory, which likely contains saved credentials and configuration, but it does not warn that this will remove authentication material and local settings. In a security-sensitive CLI context, silent credential/config deletion can cause accidental loss of access information or operational disruption, especially on shared or managed systems.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The registry examples place access keys, secrets, usernames, and passwords directly on the command line without any accompanying warning. Shell history, process listings, terminal logs, and CI job output can expose these values, making credential disclosure a realistic risk in normal use.